Lesson 17 · Gap-Patch · Unplanned insert after the Day 17 practice assessment (scored 82%)

Practice Assessment Review: Closing the Gaps

82% on the first official practice assessment — 41 of 50, weakest in Domain 2 (Architecture & Services). Nine questions missed, and they split into two kinds: a scenario-recognition pattern that showed up twice (Conditional Access), and a handful of facts genuinely never covered in Lessons 1–16. This lesson patches both before a retake.

Related lessons: L3 Service types · L4 Architectural components · L6 Networking · L7 Storage · L9 Identity & access · L13 Cost management · L14 Governance · L16 Monitoring.

The repeat: spotting Conditional Access in a scenario

Missed twice, same root cause both times: a scenario described a sign-in restricted by device compliance or which client app is being used, and MFA or RBAC got picked instead of Conditional Access.

Signal in the scenarioFeature
"Only allowed from a compliant/managed device"Conditional Access
"Only allowed from an approved client app"Conditional Access
"Prompted for a code or fingerprint at sign-in"MFA
"Granted permission to manage resources in a group"RBAC

The tell: Conditional Access questions describe a condition being evaluated (device, location, app, risk) that gates access. MFA questions describe an extra proof of identity. RBAC questions describe what someone's allowed to do, not whether they can sign in at all.

New: connecting a PaaS resource to a VNet — service endpoints

Not covered in Lesson 6 — a genuine gap, not a recall miss. A service endpoint extends a virtual network's identity to a specific Azure PaaS service (like Azure SQL Database or Storage), over the Azure backbone, so that service can be restricted to accept traffic only from that VNet's subnet.

⚠ Four networking tools, four different jobs

NSG — firewall rules (allow/deny) filtering traffic in and out, at a subnet or NIC. Service endpoint — restricts a PaaS service to accept traffic only from a specific VNet subnet. Private endpoint (Lesson 6) — gives a PaaS resource a private IP inside the VNet itself. Peering (Lesson 6) — connects two VNets directly. If a question asks "connect a VNet to an Azure SQL/Storage resource," NSG is never the answer — it only filters traffic, it doesn't create connectivity.

New: Azure Files protocols

Azure Files (Lesson 7) is accessible over SMB and NFS — not FTP, which Azure Files doesn't support at all.

New: SaaS's licensing model

Lesson 3 covered IaaS/PaaS/SaaS responsibility boundaries but not billing. SaaS is typically licensed through a flat monthly or annual subscription — one price regardless of exact usage. IaaS and PaaS stay consumption-based (Lesson 1) — pay for what you actually use. Microsoft 365 (subscription) vs. a pay-as-you-go VM (consumption) is the contrast to anchor this on.

Quick nesting check

"What's created inside a subscription?" → resource groups and resources. A management group sits above subscriptions in the hierarchy (Lesson 4) — it's not something a subscription contains, it's something a subscription can belong to.

New: Azure Advisor vs. Azure Policy

Lesson 14 paired Policy against RBAC; add a third contrast. Azure Policy — enforces compliance, can block or flag non-compliant resources automatically, mandatory. Azure Advisor (Lesson 16) — surfaces optional recommendations you choose whether to act on. "Ensure resources stay in compliance with corporate standards" is Policy's job, not Advisor's — Advisor never blocks anything.

Practice

Conditional Access is the one to watch closely on the retake — it was missed twice, not once, which is a pattern worth confirming is actually fixed rather than assuming it clicked from one explanation.
← Lesson 16: Monitoring Tools Glossary · Roadmap